A vulnerability was found in NodeBB up to 4.14.x and classified as problematic. Affected by this issue is the function renderEmoji of the component Emoji Rendering. Executing a manipulation of the argument tag.icon.url/tag.name can lead to cross site scripting.

The identification of this vulnerability is CVE-2026-73038. The attack may be launched remotely. There is no exploit available.

It is suggested to upgrade the affected component.